×
Register Here to Apply for Jobs or Post Jobs. X
More jobs:

Senior Application Security Engineer

Job in Torrance, Los Angeles County, California, 90504, USA
Listing for: Valar Atomics
Full Time position
Listed on 2026-08-30
Job specializations:
  • Security
    Cybersecurity
Salary/Wage Range or Industry Benchmark: 165000 - 190000 USD Yearly USD 165000.00 190000.00 YEAR
Job Description & How to Apply Below

About Valar Atomics

At Valar Atomics, we're redefining what's possible in energy. Our mission is to make clean, high-temperature nuclear power scalable—unlocking abundant energy for industry, hydrogen, and next-generation manufacturing. We are a team of builders, engineers, and operators who believe nuclear energy should be fast to deploy, factory-made, and built for the real world. Our first pilot plant in Orangeville, Utah will demonstrate how advanced nuclear systems and fuel fabrication can power the future.

Joining Valar Atomics means becoming part of a company where autonomy, ownership, and impact exist at every level.

The Team

As part of the Business organization, IT & Enterprise Software delivers the technology infrastructure, enterprise applications, and digital tools that power Valar's operations. The team ensures secure, reliable, and scalable technology solutions that support every function across the company.

The Role

We are seeking a Senior Application Security Engineer to embed security directly into the software development lifecycle for custom applications handling Controlled Unclassified Information (CUI) and ITAR-regulated data, in an environment governed by CMMC 2.0, Department of Energy (DOE) cybersecurity requirements, and Nuclear Regulatory Commission (NRC) cyber security standards. This role partners closely with software engineering teams building custom applications and APIs primarily in Python and Java, deployed on AWS, Azure, Palantir Foundry, Kubernetes, and Git Hub, and helps establish secure, compliant patterns for integrating AI tools (Claude, OpenAI) into engineering workflows without compromising data protection, safeguards, or regulatory obligations.

You will be the security subject-matter expert embedded with development teams — reviewing designs, threat-modeling new features, hardening pipelines, and ensuring every system handling CUI/ITAR/UCNI data meets DOE order requirements, 10 CFR 73.54, NRC Regulatory Guide 5.71, and CMMC 2.0 (NIST SP 800-171/800-172) controls by design, not as an afterthought. This role also contributes lightweight security architecture guidance — reference patterns, boundary/trust-zone diagrams, and control mappings — to keep new systems aligned with the broader security architecture as they're designed, without owning full enterprise architecture responsibilities.

Key Responsibilities
  • Partner with software engineers throughout design, development, and deployment to identify and remediate security risks in custom applications processing CUI, ITAR, and Unclassified Controlled Nuclear Information (UCNI).
  • Perform threat modeling, secure architecture reviews, and design reviews for new features and services, with particular attention to data flows across AWS, Azure, and Palantir Foundry.
  • Conduct manual and tool-assisted secure code review of Python and Java codebases, identifying issues such as injection flaws, insecure deserialization, broken authentication/authorization, and insecure cryptographic usage.
  • Review and harden API design and implementation (REST/GraphQL) — authentication and authorization schemes (OAuth 2.0/OIDC, mTLS), input validation, rate limiting, schema validation, and API gateway configuration — across internally built and third-party-integrated APIs, including AI service APIs (Claude, OpenAI).
  • Contribute light-touch security architecture artifacts — data flow diagrams, trust-zone/boundary diagrams, and control-to-requirement mappings — to help engineering teams design new systems in alignment with existing security architecture and reference patterns; elevate to enterprise/security architecture as needed for larger initiatives.
  • Own and mature the application security program aligned to CMMC 2.0 Level 2 (NIST SP 800-171, and 800-172 where required), including SSP and POA&M maintenance for application-layer scope.
  • Support DOE cybersecurity program requirements (e.g., DOE O 205.1, DOE O 471.6, RMF per NIST SP 800-37) for systems and applications supporting DOE contracts or facilities.
  • Support NRC cyber security program alignment (10 CFR 73.54, Regulatory Guide 5.71) for applications supporting critical digital assets,…
Position Requirements
10+ Years work experience
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary